CVE-2022-1943Out-of-bounds Write in Kernel

CWE-787Out-of-bounds Write16 documents7 sources
Severity
7.8HIGHNVD
OSV5.5
EPSS
0.0%
top 88.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateSep 21

Description

A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages11 packages

NVDlinux/linux_kernel5.155.15.40+1
Debianlinux/linux_kernel< 5.17.11-1+2
Ubuntulinux/linux_kernel< 5.15.0-47.51
CVEListV5linux/linux_kernelLinux kernel 5.18-rc7
debiandebian/linux< linux 5.17.11-1 (bookworm)

Patches

🔴Vulnerability Details

7
OSV
linux-hwe-5.15, linux-lowlatency-hwe-5.15 vulnerabilities2022-09-21
OSV
linux-intel-iotg vulnerabilities2022-09-16
OSV
linux-raspi vulnerabilities2022-09-08
OSV
linux-oracle vulnerabilities2022-09-05
OSV
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-gkeop, linux-ibm, linux-kvm, linux-lowlatency vulnerabilities2022-09-02

📋Vendor Advisories

8
Ubuntu
Linux kernel (HWE) vulnerabilities2022-09-21
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2022-09-16
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2022-09-08
Ubuntu
Linux kernel (Oracle) vulnerabilities2022-09-05
Ubuntu
Linux kernel vulnerabilities2022-09-02